Dashboardcrafttar-fs pinned at 1.16.6 via override (t…

tar-fs pinned at 1.16.6 via override (tar-stream@1.x preserved)

Category: decision
Confidence: 1.00
ID: 019fdd1b-e164-7bec-ae67-53b567a18e63
Project ID: e16af391-c497-4837-b681-c849a5514499
Cross-project: No
Recalled in other projects: 0
Source session: 1LCorxku9DNLu5w5f
Created: 2026-08-07 15:30:37
Updated: 2026-08-07 16:43:39

Content

craft pins tar-fs at 1.16.6 via root pnpm override tar-fs@<1.16.4: 1.16.6 because @vercel/client exact-pins vulnerable 1.16.3 (GHSA-pq67-2wwv-3xjx / CVE-2024-12905 link-following + path traversal, GHSA-8cj5-5rvv-wf4v, GHSA-vj76-c3g6-qr5v). 1.16.6 (latest patched 1.x) keeps the tar-stream@1.x dependency tree; jumping to 2.x would switch tar-stream from 1.x to 2.x. In craft's usage the vulnerability is unreachable — @vercel/client only calls pack() (archive.js createTgzFiles); the advisories are in extract — but dependency-review gates the merge anyway. Verified via npm audit API: 1.16.4 and 1.16.6 report 'advisories: none'.

Move to: